Navigating Digital Sovereignty and Strategic Cloud Choices 

TL;DR

Digital sovereignty is no longer just a buzzword – it’s a strategic imperative. In our webinar on March 5, Levi9 Cloud experts Boudewijn HaasNikola Djordjevic, and Codrin Baleanu explored what it really means, why it matters now, and how to approach it without sacrificing innovation. The key takeaway: sovereignty is about balance – compliance, control, and continuity. 

Why It's a Strategic Decision Now

Not long ago, moving to the cloud was a no-brainer. Today, it’s a deliberate choice that requires weighing risks carefully. We opened the webinar with a real example: a financial customer that planned to migrate most workloads to a major hyperscaler – but changed course after identifying cloud as a risk. As a bank, they needed a clear exit strategy to stay compliant with DORA and NIS2. 

 

This isn’t unique. Organizations across industries are increasingly aware of the US Cloud Act and the Patriot Act – legislation that can compel American companies to disclose data regardless of where it’s stored. 

The Four Pillars of Digital Sovereignty

Digital sovereignty is about controlling your data, operating your systems, and staying aligned with regulations – without foreign dependency. It rests on four pillars: 

 

  • Data sovereignty: control over residency, classification, encryption, and auditability 
  • Operational sovereignty: the ability to run and maintain systems independently 
  • Technical sovereignty: portability through open source technologies like Kubernetes and OpenStack 
  • Legal sovereignty: alignment with EU regulations (GDPR, NIS2, DORA) over conflicting foreign legislation 

 

The goal: an audit-ready environment at all times. 

Does Sovereignty Limit Innovation?

It doesn’t have to. As Codrin explained, if you follow industry standards and are thoughtful in your approach, you should not need to sacrifice speed or agility. Digital sovereignty is fundamentally about resilience, independence, and understanding the boundaries within which you operate – whether at a regional, national, or global scale. 

 

A practical approach involves a few key steps. First, understand your compliance tier – not all workloads carry the same regulatory burden. Financial, telecom, and industrial sectors face stricter requirements than a smaller retail operation. Second, leverage open source and containerization: technologies like Kubernetes and OpenStack provide a portable, decoupled foundation that lets you move workloads between private and public cloud based on criticality. Third, use cloud native services where compliance pressure is lower – they offer a strong balance between cost and operational overhead. Fourth, apply zero trust security principles, ensure encryption in transit and at rest, and wherever possible own your own encryption keys. Fifth, think in disaster recovery scenarios – from a minimal “pilot light” environment to a fully mirrored setup for critical workloads. 

 

All three major hyperscalers now offer EU-specific sovereign cloud solutions – AWS with a fully isolated partition in Germany, Google Cloud through European partnerships, and Azure with EU-only personnel and data residency. European providers like OVH Cloud, Hetzner, and StackIT are also viable options for stricter compliance scenarios, and OpenStack remains a strong open source alternative for organizations that need full control and portability. 

Where to Start

Start by assessing your compliance needs. If regulation demands action, prioritize. If not, put the sovereignty pillars on your backlog and work through them incrementally. 

 

For a structured starting point, we offer a focused two-hour digital sovereignty workshop – an interview-based review of your posture across all four pillars, resulting in a scorecard with actionable insights. Ideal participants: CIO, CTO, or anyone with a solid overview of your data landscape and business continuity requirements. 

In this article:

Related posts

June 26th

The Cost of Choice

Most companies spend up to 40% to much on cloud, are you? Cut spend, not options. Smart standardizations win.

Cloud cost overruns and growing technical debt rarely stem from tooling alone—they are symptoms of architectural and operational choices. This session looks at how senior technical leaders can regain control by connecting cloud spend directly to business value. We’ll explore unit‑economics thinking, ownership models, and lifecycle management practices that reduce waste while preserving delivery speed. You’ll learn how to combine FinOps principles with technical‑debt controls to create a cloud environment that is financially sustainable and technically healthy.

May 28th

AI AGENTS DESERVE AI PLATFORM

Portable patterns for Azure, AWS and GCP that survive the next upgrade

AI agents are moving rapidly from experimentation into real production use cases, but architectures vary widely across cloud platforms. In this webinar, we compare practical patterns for building and running AI agents on Azure, AWS, and Google Cloud Platform. We’ll focus on what to standardize, where to embrace cloud‑native capabilities, and how to design for security, observability, and future change. The goal is not to pick a winner, but to help leaders understand how to scale agent‑based solutions without locking themselves into fragile designs.

April 23rd

Winning on Repeat: Product Engineering in the Age of AI

Cadence, quality and outcomes over output

Delivering a successful solution once is no longer enough. In the age of AI, organizations need product engineering models that enable them to win consistently across teams, releases, and markets. This session explores how leading organizations evolve from project‑centric delivery to product‑centric execution, supported by AI‑augmented engineering practices. We’ll look at cadence, quality, and accountability, and how leadership decisions shape sustainable delivery performance over time.

April 2nd

GOVERNING AI IN PRODUCTION

Designing cloud and data platforms that survive real-world pressure

Many organizations succeed in building AI proofs of concept, far fewer succeed in scaling them safely into production. This webinar focuses on what it takes to move from experimentation to reliable, governed AI platforms. We’ll discuss platform architecture choices, model governance, security, and policy patterns that enable teams to deploy AI at scale without slowing down delivery. Designed for senior technical leaders, this session provides practical guidance on turning AI initiatives into durable capabilities that deliver value beyond the first demo

March 5th

Navigating Digital Sovereignty and Strategic Cloud Choices

How Organizations Can Balance Innovation, Compliance, and Control in a Multi-Cloud World

In today’s rapidly evolving digital landscape, organisations face increasing pressure to ensure business continuity, maintain public trust, and comply with complex regulations like NIS2, DORA, and GDPR. This webinar explores the critical concepts of digital and operational sovereignty, the strategic importance of hybrid and sovereign cloud models, and the risks of vendor lock-in.